← Home

@storm-software/tsdown

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

acidiccyclone-uitsdownmonorepostormstorm-opsstorm-stacksullivanpj

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): SLSA provenance attestation present; gitHead absence is a minor metadata gap, not a supply chain risk for this publisher. ai
provenance publisher-changed AI (provenance): Transition from stormie-bot to GitHub Actions CI publisher; SLSA provenance attestation confirms legitimate CI/CD pipeline. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are first-party Storm Software monorepo packages; consistent with internal refactoring pattern across 459 versions. ai
phantom-deps phantom-dep:rolldown AI (phantom-deps): Declared runtime dep; bundler integration, stable false positive. ai
phantom-deps phantom-dep:commander AI (phantom-deps): Declared runtime dep; CLI binary uses commander, stable false positive. ai
phantom-deps phantom-dep:tsup AI (phantom-deps): Declared runtime dep in package.json; used via config/build toolchain, not direct import. ai
phantom-deps phantom-dep:source-map AI (phantom-deps): Declared runtime dep; source map handling in build output, stable false positive. ai
phantom-deps phantom-dep:@storm-software/config-tools AI (phantom-deps): Same-org dep declared in dependencies; stable false positive for this package family. ai
phantom-deps phantom-dep:es-toolkit AI (phantom-deps): Declared runtime dep; utility library used in build toolchain. ai
phantom-deps phantom-dep:globby AI (phantom-deps): Declared runtime dep; used in config/build utilities, stable false positive for this package. ai
phantom-deps phantom-dep:chokidar AI (phantom-deps): Declared runtime dep; used in watch/build toolchain, stable false positive. ai

Versions (showing 100 of 528)

Version Deps Published
0.45.270 12 / 8
0.45.269 12 / 8
0.45.268 12 / 8
0.45.267 12 / 8
0.45.266 12 / 8
0.45.265 12 / 8
0.45.262 12 / 8
0.45.260 12 / 8
0.45.259 12 / 8
0.45.253 12 / 8
0.45.252 12 / 8
0.45.251 12 / 8
0.45.250 12 / 8
0.45.247 12 / 8
0.45.246 12 / 8
0.45.245 12 / 8
0.45.244 12 / 8
0.45.243 12 / 8
0.45.242 12 / 8
0.45.241 12 / 8
0.45.240 12 / 8
0.45.239 12 / 8
0.45.238 12 / 8
0.45.237 12 / 8
0.45.236 12 / 8
0.45.235 12 / 8
0.45.234 12 / 8
0.45.233 12 / 8
0.45.232 12 / 8
0.45.231 12 / 8
0.45.230 11 / 9
0.45.229 11 / 9
0.45.228 11 / 9
0.45.227 11 / 9
0.45.226 11 / 9
0.45.225 11 / 9
0.45.224 11 / 9
0.45.223 11 / 9
0.45.222 11 / 9
0.45.221 11 / 9
0.45.220 11 / 9
0.45.219 11 / 9
0.45.218 11 / 9
0.45.217 11 / 9
0.45.216 11 / 9
0.45.215 11 / 9
0.45.214 11 / 9
0.45.213 11 / 9
0.45.212 11 / 9
0.45.211 11 / 9
0.45.210 11 / 9
0.45.209 11 / 9
0.45.208 11 / 9
0.45.207 11 / 9
0.45.206 11 / 9
0.45.205 11 / 9
0.45.204 11 / 9
0.45.203 11 / 9
0.45.202 11 / 9
0.45.201 11 / 9
0.45.200 11 / 9
0.45.199 11 / 9
0.45.198 11 / 9
0.45.197 11 / 9
0.45.196 11 / 9
0.45.195 11 / 9
0.45.194 11 / 9
0.45.193 11 / 9
0.45.192 11 / 9
0.45.191 11 / 9
0.45.190 11 / 9
0.45.189 11 / 9
0.45.188 11 / 9
0.45.187 11 / 9
0.45.186 11 / 9
0.45.185 11 / 9
0.45.184 11 / 9
0.45.183 11 / 9
0.45.182 11 / 9
0.45.181 11 / 9
0.45.180 11 / 9
0.45.179 11 / 9
0.45.178 11 / 9
0.45.177 11 / 9
0.45.176 11 / 9
0.45.175 11 / 9
0.45.174 11 / 9
0.45.172 11 / 9
0.45.171 11 / 9
0.45.170 11 / 9
0.45.169 11 / 9
0.45.168 11 / 9
0.45.167 11 / 9
0.45.166 11 / 9
0.45.163 11 / 9
0.45.162 11 / 9
0.45.161 11 / 9
0.45.160 11 / 9
0.45.159 11 / 9
0.45.158 11 / 9
Showing 100 of 528 Next page →

v0.45.270

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.269

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.268

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.267

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.266

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.265

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.262

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.260

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.259

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.253

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.252

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.251

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.250

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.247

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.246

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.245

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.244

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.243

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.242

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.241

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.240

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.45.239

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.